added a sample job manifest named `multus-validation` that
validates the multus configuration in the cluster.
Signed-off-by: Nikhil-Ladha <nikhilladha1999@gmail.com>
in the existing node watcher, we'll check for node update
event and see if there are `out-of-service` taints are applied
and `ROOK_WATCH_FOR_NODE_FAILURE` is enabled in rook-ceph-operator-configmap,
if then we'll create the networkFence cr and delete the cr if nodes come back.
And, added the unit test too.
Signed-off-by: subhamkrai <srai@redhat.com>
adding drop `ALL` capabilities in rook operator container
as this is not required and will remove warning in ocp cluster.
Signed-off-by: subhamkrai <srai@redhat.com>
Without deletecollection capability the image pullers won't be deleted, causing multus validation to fail.
Added deletecollection verbs to the daemonsets resource in role rook-ceph-system
This is fix for Issue: https://github.com/rook/rook/issues/12435
Signed-off-by: Sudharsan Omprakash <sudharsan.omprakash@yahoo.com>
import script may be need a re-run if other
resources need to be configured
for ex: if rbd is configured and later on point
someone want to also configure rgw, it will have
a choice
Closes: https://github.com/rook/rook/issues/12412
Signed-off-by: parth-gr <paarora@redhat.com>
with `requiredDropCapabilities: ["All"]` we can
drop all the default privileges and we can add the
privileges required `allowedCapabilities:` here.
Signed-off-by: subhamkrai <srai@redhat.com>
Documentation and examples used a deprecated annotation to set the Ingress class name. This commit replaces it with the correct version using spec.ingressClassName .
Signed-off-by: Marcel Lautenbach <mlautenb@gmail.com>
The stretch clusters must create pools with a pool spec
that is valid for the stretch scenario, with 4 replicas
and failure domain and sub failure domain as needed
to match the topology. Otherwise, ceph will create a
default .mgr pool which will have replica 3 which is
invalid for the stretch scenario.
Signed-off-by: travisn <tnielsen@redhat.com>
We add a new field domainName to the Kerberos section. The field is used
to setup /etc/idmapd.conf with the domain name. This allows idmapper to
map to kerberos credential to the correct uid/gid.
We add Spec.Security.Kerberos.DomainName to the CRD
Signed-off-by: Sachin Prabhu <sprabhu@redhat.com>
These rbac changes were introduced as part of #11845 PR to enable
sidecar accessing mgr pods but in fact they are not necessary
as rook-ceph-mgr role had already the ability to update pods
Closes: https://github.com/rook/rook/issues/12336
Signed-off-by: Redouane Kachach <rkachach@redhat.com>
1) donot change rgw fqdn to ip if provided,
As now the bucket class supports the
entry of fqdn
2) update crds with new description in EndpointAddress
Signed-off-by: parth-gr <paarora@redhat.com>
This adds the new `exporter:` resource key to the Ceph cluster example
yaml. It also set some sane resource requests and limits for it in the
CephCluster section of the rook-ceph Helm chart.
Closes#11914
Signed-off-by: Alexander Trost <galexrt@googlemail.com>
The service monitor selectors need to match the mgr service labels.
Since the mgr service labels don't use the mgr_role (only the mgr
service selectors use the mgr_role), the mgr_role should be removed
from the service monitor.
Signed-off-by: travisn <tnielsen@redhat.com>
if there is no multisite config pass, it will still checks for
the zones and zones group and not able to query anything
Signed-off-by: parth-gr <paarora@redhat.com>
there were some places where rulenamesapce was present updated to rulesNamespaceOverride
Closes: rook#12163
Signed-off-by: parth-gr <paarora@redhat.com>
The prometheus mgr module and ceph exporter can now be optionally
disabled by the monitoring.metricsDisabled setting in the
CephCluster CR. These will not be disabled by default, rather
than the mgr module being disabled by default from v1.11.4.
Signed-off-by: travisn <tnielsen@redhat.com>
the check validate_rgw_multisite was always checking for realm
updated it to check the specific config
fixed validate_rgw_endpoint pool validation
added missing realm zonegroup and zone while interacting with user resources
Co-authored-by: Sergio Pérez Fernández <sergioperez794@gmail.com>
Signed-off-by: parth-gr <paarora@redhat.com>
Pare down the available volume sources for NFS config files so that the
CRD isn't unnecessarily huge. This allows us to recommend
`kubectl apply` again in the upgrade doc.
Size of the NFS CRD is reduced by approximately 60%.
Signed-off-by: Blaine Gardner <blaine.gardner@redhat.com>
The journal size was only applicable to the filestore OSD
format which has not been supported by rook since v1.2.
Remove the remaining obsolete setting from the examples and
code.
Signed-off-by: travisn <tnielsen@redhat.com>
Add --skip-monitoring-endpoint to create-external-cluster-resources.py
to allow the script to work with Ceph clusters without an enabled
prometheus module.
Document the new flag in external-cluster.md and add relevant unit tests
Signed-off-by: Angelos Kolaitis <neoaggelos@gmail.com>
if restricted permission was on the . was appended to k8s secret and
failed to create the secret so added a alias name is user wan't to suuport
pool with . in name
Signed-off-by: parth-gr <paarora@redhat.com>
With the release of ceph v17.2.6, the examples and the base
image for the operator are updated to pick up the latest
and greatest.
Signed-off-by: travisn <tnielsen@redhat.com>
ClusterID uniquely identifies a cluster. It is used as a prefix to
nslookup exported services.
For example: <clusterid>.<svc>.<ns>.svc.clusterset.local
Signed-off-by: sp98 <sapillai@redhat.com>